compromised

8 stories and discussions about compromised, aggregated from every source we track.

1.

EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.

6 points•joozio•8 days ago•0 comments•
2.

Mini Shai-Hulud malware was injected into keyv and eight related npm packages on August 4, 2026 after an attacker compromised the maintainer's GitHub account

5 points•dbremner•about 2 months ago•0 comments
3.

EvilTokens provided an end-to-end platform that makes mass compromises faster and easier.

3 points•noashavit•5 days ago•0 comments•
4.
3 points•chrisaycock•9 days ago•1 comment•
5.

I checked every action of my own Claude Code agent against a profile of how I work and a set of org policies, using Jev. It caught 14 of 14 attacks for $0.15 per 1,000 events.

2 points•kunalsin9h•3 days ago•0 comments•
6.

Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

2 points•justsomehuman•6 days ago•1 comment•
7.

The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are…

2 points•joshcsimmons•7 days ago•0 comments•
8.

Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span. Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts. Minutes, not days “While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said . “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.” Read full article Comments

0 points•Dan Goodin•8 days ago•0 comments

Related topics